Getting Data In

Getting Data In
Community Activity
naydenk
Hello I have multiple client UFs sending to an intermediary UF, which then forwards to an indexer. Sporadically, the...
by naydenk Path Finder in Getting Data In 11-09-2012
3 13
3
13
unyalli
I'm reading syslog data and have a netfilter (iptables) firewall that logs entries that start with FW_. When doing a ...
by unyalli New Member in Getting Data In 11-09-2012
0 3
0
3
EStallcup
I know this is probably something simple, but for some reason after upgrading my local instance of splunk to version ...
by EStallcup Path Finder in Getting Data In 11-09-2012
1 1
1
1
jm8thew
I'm new to splunk and I'm trying to import some data from a database that I'd like to have indexed by Splunk. I have ...
by jm8thew Engager in Getting Data In 11-09-2012
0 1
0
1
las
I have a date in my input files 08-11-12, This date could be August 11. 2012, or (as is the case) November 8. 2012, a...
by las Builder in Getting Data In 11-09-2012
0 6
0
6
rechteklebe
Hello together, i would like to see in a search the amount of affected user. Sometimes there are more events related...
by rechteklebe Path Finder in Getting Data In 11-09-2012
0 1
0
1
officeguy
Hi, What is the actual process by which the events are 'forwarded' into splunk. The ps1 script gets events and does ...
by officeguy Explorer in Getting Data In 11-08-2012
1 14
1
14
JelianeL
9/12/12 2:25:57.000 PM Hi all, Above is my timestamp and I'm using "%d/%m/%Y %H:%M:%S %p" The format that I used r...
by JelianeL Explorer in Getting Data In 11-08-2012
0 2
0
2
peter_gianusso
Functionally, here's what I am looking to do. I want to take the host (NJROS1BVA0597), append the source type (VM88 o...
by peter_gianusso Communicator in Getting Data In 11-08-2012
0 1
0
1
cgisplunk
Hi everyone, I've read the deployment docs and it looks like it will not work if our XenApp runs on Windows 2003 32-...
by cgisplunk Path Finder in Getting Data In 11-08-2012
0 2
0
2
diegosainz
I am able to gather Windows 2008 logs with no problems, but when I add a forwarder to a Windows 2003 box I get no log...
by diegosainz Path Finder in Getting Data In 11-08-2012
0 2
0
2
tincupchalice
So I tried pattern as \d{18} for events looking like: 1351623403000225565 Type=VARIABLE, blah blah 13516234030002255...
by tincupchalice Path Finder in Getting Data In 11-08-2012
0 4
0
4
rmckerchar
Hi guys, I'm trying to define a search to spot Active Directory domain controllers which have not (and possibly neve...
by rmckerchar New Member in Getting Data In 11-08-2012
0 3
0
3
ezajac
I haven’t set this type of input before. I have logs available over http from a URL like below. The typical user view...
by ezajac Path Finder in Getting Data In 11-08-2012
0 1
0
1
perlish
There're 300G disk space in my server, how can I delete or archive old data in splunk ? Thank you !
by perlish Communicator in Getting Data In 11-08-2012
0 1
0
1
104K
Hi I have series of two key-value pairs (timestamp and some other key) on one json file, which looks like below: {"...
by 104K Engager in Getting Data In 11-08-2012
3 2
3
2
halperkins
I have a field called size that takes the form: 1 2 3 4 I want to find someway to evaluate size so that is sums all...
by halperkins New Member in Getting Data In 11-07-2012
0 1
0
1
aschoen
I am trying to forward input from a universal forwarder to a regular Splunk installation on my desktop. The universa...
by aschoen New Member in Getting Data In 11-07-2012
0 1
0
1
SramanJ
Hello, I am a new user to splunk and logging in general. So, appreciate your patience if my questions are fairly sim...
by SramanJ Engager in Getting Data In 11-07-2012
6 1
6
1
aandrew
Hi, is anyone out there having a Slow search and missed alerts on Search head. we have installed search head on 64 bi...
by aandrew New Member in Getting Data In 11-07-2012
0 9
0
9
Ricapar
We have a very large environment.. and with Splunk charging by the GB/day, we obviously have an interest in controlli...
by Ricapar Communicator in Getting Data In 11-07-2012
0 4
0
4
bread555
One of my sources coming from a universal forwarder needs to have have it's truncate option set to 0. I have edited ...
by bread555 Explorer in Getting Data In 11-07-2012
1 2
1
2
sruthy
Hi, I am new to splunk and when i add datainputs i was not known about the timestamp issue and later i explored it. w...
by sruthy Explorer in Getting Data In 11-07-2012
1 1
1
1
pdherndon
I have configured approx. 100 access points to send syslog events to both Splunk and to a kiwi syslog server I have s...
by pdherndon New Member in Getting Data In 11-06-2012
0 8
0
8
the_wolverine
I've heard that Splunk recommends monitoring of rolled log files (eg. file.log.1, file.log.2, etc) under certain sit...
by the_wolverine Champion in Getting Data In 11-06-2012
0 3
0
3
Get Updates on the Splunk Community!

Continue Your Federation Journey: Join Session 3 of the Bootcamp Series

To help practitioners build a stronger foundation, we launched the Data Management & Federation ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Casting Call: Compete in Cyber Games

Lights, Camera, SecOps: Apply to Compete in Cyber Games     Think you have what it takes to beat the clock? ...
Top Solution Authors